CVE-2026-91011: EWWW Image Optimizer < 8.7.7 - Author+ Stored XSS via Image Class Attribute Backreference Expansion
Published Sep 17, 2026
·Updated
The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is stored in published content and executes in the browser of any user who later views the affected page.
Affected Software
1 affected component
WordPress plugin EWWW Image Optimizer<8.7.7
Event History
Sep 17, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue, and who is affected when it is triggered?
An authenticated WordPress user with the Author role or higher can inject JavaScript into published content. The script executes in the browser of any user who later views an affected page.
2
What plugin versions require remediation?
EWWW Image Optimizer versions before 8.7.7 are affected. Update the plugin to version 8.7.7 or later.